With register_globals turned off by default, I suggest you use $_SERVER['HTTP_REFERER'] instead of $HTTP_REFERER.
But like edwardsbc said it, it is totally unreliable ! Many browsers can be set up so they don't send referers... Also, it is easily changeable, so it is worth absolutely nothing for security...